Share encrypted text with end-to-end encryption. The server never sees your content or your decryption key.
A realistic look at what Nobins stores and what stays in the share link
Incident note Rotated the staging Stripe webhook secret at 2026-06-27 09:30 UTC. Owner: platform-oncall Next step: remove the old value from Vercel after deploy.
nHmAqFKLpYy-OYDOLmKtXkXimNm6J_3zFSEmaJeVOMO4alNftOkuaH_uQc3rmDSaogZUJ1zjuwxC4-b1LLq1ZourlCI3YLBnOgPUD8FODhwVS5McENacaQ
UTPLjkn3AztAWZ8q_T7-kP8O...
aIYNtoq_uPNwCaVLkDaKi3C3Wf8m5CwN
allQyNaoUBXeJUVf4dFybjExYHmQ66nBx1uUpqdaZc4Zwll9Vm95cBCiUROOj4K3...
86 chars (88B decoded)
nobins.com/p/demo#allQyNaoUBXeJUVf4dFy...
Content is encrypted in your browser before it ever touches the server. The server stores only ciphertext.
The decryption key lives in the URL fragment (#), which is never sent to the server. No key, no access.
Open mode keeps share links compact. Sealed mode adds ML-KEM-1024, which makes stronger but much longer links.
Set a TTL or self-destruct on read. Expired pastes are removed the next time they are opened.
Create and share pastes instantly. No email, no signup, no tracking.
The server cannot read your pastes. It only stores encrypted blobs and serves them back on request.